ninjitzu.
SECURITY MODEL

Local-first by design.

The safest unnecessary upload is the one that never happens.

Browser boundary

Supported file inspection, image repair and screenshot OCR are designed to run in the browser. Downloaded code can read only the files the user deliberately selects through browser controls.

No secret keys in the page

Payment and account secrets must remain on protected backend services. The public HTML contains no Stripe secret key, database service-role key or unrestricted AI credential.

Verification boundaries

Ninjitzu blocks PASS when a supplied requirement remains unresolved. Structural PDF repair, encryption removal and other advanced operations must use a compatible engine and cannot be claimed merely because a file was selected.

Safe use

Keep the original, inspect the output and avoid processing untrusted files in an outdated browser. The local-first model reduces server exposure but does not eliminate browser, extension or device risk.

Reporting

Use the contact page to report a vulnerability. Include reproducible technical details but never include another person’s private document.